Current Activity Calendar
| October 02, 2007 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
Google's Gmail XSRF Vulnerabilityadded October 2, 2007 at 09:10 am | updated October 2, 2007 at 09:11 am
US-CERT is aware of a publicly reported cross-site request forgery vulnerability in Google's Gmail. A cross-site request forgery vulnerability may allow a request from an attacker to be interpreted as originating from an authenticated user. Public reports indicate that this vulnerability may allow an attacker to create arbitrary filters for a user's Gmail account. Apple Releases Update for iPhoneadded September 27, 2007 at 03:29 pm
Apple has released an update to address several vulnerabilities in the iPhone. These vulnerabilities may allow an attacker to execute arbitrary code or commands, cause a denial-of-service condition, or conduct cross-site scripting attacks on an affected device. CA BrightStor Hierarchical Storage Manager Vulnerabilitiesadded September 27, 2007 at 09:55 am
US-CERT is aware of several vulnerabilities that affect the CA BrightStor Hierarchical Storage Manager version r11.5. These vulnerabilities may allow an attacker to execute arbitrary code or gain control of the system. Cisco Products Loopback Vulnerabilityadded September 27, 2007 at 09:25 am
Cisco has released a Security Response regarding a vulnerability in the way that Cisco Catalyst 6500 and Cisco 7600 series devices use addresses from the loopback range. Cisco reports that an attacker can exploit this to bypass access control lists. CA ARCserve Backup for Laptops and Desktops contains multiple vulnerabilitiesadded September 24, 2007 at 03:02 pm
US-CERT is aware of several vulnerabilities that affect the CA ARCserve Backup for Laptops and Desktops product. These vulnerabilities may allow an attacker to execute arbitrary code, bypass authentication, or cause a denial-of-service condition. Google Search Appliance Vulnerabilityadded September 24, 2007 at 12:28 pm
US-CERT is aware of a publicly reported cross-site scripting (XSS) vulnerability in Google's search appliance. Cross-site scripting vulnerabilities may allow a remote, unauthenticated attacker to inject malicious script into a web page. Reports of Multiple Product PDF Rendering Vulnerabilityadded September 21, 2007 at 03:24 pm
US-CERT is aware of public reports of a vulnerability that may affect Adobe Acrobat, Adobe Acrobat Reader, and Foxit Reader. Few details are currently available, but it is claimed that an attacker may be able to execute arbitrary code or commands on an affected system by enticing a user to open a specially crafted PDF document.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
